← back
CVE-2021-42392CWE-502

CVE-2021-42392

40Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 83%
exploitation probability
83%top 1% of all CVEs
observed exploitation
nono source reports it
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Affected
13 products
Red Hat BPM Suite 6 · Red Hat Integration Camel Quarkus 1 · Red Hat JBoss BRMS 5 · Red Hat JBoss BRMS 6 · Red Hat JBoss Data Grid 7 · and others 8
no_fix_planned: Out of support scope
Fixed
12 products (82 components)
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server · Red Hat Single Sign-On 7.6 for RHEL 9 · Red Hat Single Sign-On 7.5 for RHEL 7 Server · Red Hat Single Sign-On 7.5 for RHEL 8 · Red Hat Single Sign-On 7.6 for RHEL 7 Server · and others 7
Not affected
7 products (233 components)because the vulnerable code is not present in the product
Red Hat JBoss EAP 7.4 for RHEL 7 Server · Red Hat JBoss EAP 7.4 for RHEL 8 · Red Hat Decision Manager 7 · Red Hat Fuse 7 · Red Hat Integration Camel K 1 · and others 2
The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI servers, causing remote code execution. This can be exploited through various attack vectors, most notably through the H2 Console which leads to unauthenticated remote code execution.
Affected products
h2database · h2